Security Leftovers

-
Human Rights Groups Warn UN Cybercrime Treaty Must Avoid 'Chilling Effect'
Ahead of a United Nations session next week, nearly 130 academics and advocacy groups asserted that "it is vitally important to apply a human rights-based approach" to drafting a potential cybercrime treaty.
"A convention without such safeguards or that dilutes states' human rights obligations would place individuals at risk and make our digital presence even more insecure."
-
Nearly 130 Public Interest Organizations and Experts Urge the United Nations to Include Human Rights Safeguards in Proposed UN Cybercrime Treaty
The proposed treaty will likely deal with cybercrime, international cooperation, and access to potential digital evidence by law enforcement authorities, as well as human rights and procedural safeguards. UN member states have already written opinions discussing the scope of the treaty, and their proposals vary widely. In a letter to the committee chair, EFF and Human Rights Watch along with partners across the world asked that members include human rights considerations at every step in the drafting process. We also recommended that cross-border investigative powers include strong human rights safeguards, and that global civil society be provided opportunities to participate robustly in the development and drafting of any potential convention.
Failing to prioritize human rights and procedural safeguards in criminal investigations can have dire consequences. As many countries have already abused their existing cybercrime laws to undermine human rights and freedoms and punish peaceful dissent, we have grave concerns that this Convention might become a powerful weapon for oppression. We also worry that cross-border investigative powers without strong human rights safeguards will sweep away progress on protecting people’s privacy rights, creating a race to the bottom among jurisdictions with the weakest human rights protections.
We hope the Member States participating in the development and drafting of the treaty will recognize the urgency of the risks we mention, commit to include civil society in their upcoming discussions, and take our recommendations to heart.
-
EFF Asks Appeals Court to Rule DMCA Anti-Circumvention Provisions Violate First Amendment
-
EFF Threat Lab’s “apkeep” APK Downloader, Now More Capable and Available in More Places
In addition to the ability to download Android packages from the Google Play Store and APKPure, we’ve added support for downloading from the free and open source app repository F-Droid. Packages downloaded from F-Droid are checked against the repository maintainers’ signing key, just like in the F-Droid app itself. The package index is also cached, which makes it easy to run multiple subsequent requests for downloads.
You can now download specific versions of apps from either the apk-pure app store, which mirrors the Google Play Store, or from f-droid. To try it, issue the following command to see which versions are available:
Once you’ve picked a desired version, download it with this command:
-
Microsoft touts first PCs to ship natively with secure Pluton chip [Ed: This is not about security at all]
Asked why the chip is initially disabled, the spokesperson said enterprise customers "have told us they extensively test and evaluate any new security-related software or feature that will be introduced into their network and can choose to enable Pluton on their devices as they see fit. As Pluton rolls out into market and we have time to assess the customer demand for factory enablement, we will review enabling [it]."
The Pluton processor is aimed at delivering greater protection than the existing Trusted Platform Module (TPM) as it’s a dedicated security chip that handles security features such as BitLocker, Windows Hello, and System Guard.
-
AWS is Not a Dumb Pipe
The telcos didn't go down without a fight. They successfully got so many regulations passed against VoIP that it served a serious barrier to entry for more than a decade. The hyperscalers have an even better card to play than regulation: open source. By bringing the cost of software down to zero, they can commoditize their complement. If AWS open sourced all higher-level services, they would still be a "dumb pipe", but with fewer competitors.
-
“Biggest cyber breach in history” as techs scramble to be heard above Omicron din [Ed: A bit of a distraction from the greater perils]
The devil child of the moment, if you want to call it that, is the very technically named Log4j computer vulnerability, which has left governments and corporations world wide open to attack and scrambling to patch, or repair, their systems. It is being called the biggest cyber security breach in history.
With the news bandwidth consumed by Omicron and the public immured to cyber scare stories, the scale of the recent Log4j story and the implications it has for the secure operation of government services and infrastructure is only just becoming more broadly understood.
-
Google calls for new government action to protect open-source software projects [Ed: Meeting stacked by the worst culprits, as usual]
Following a summit on open-source security hosted at the White House Thursday, Google has called for increasing government involvement in identifying and securing critical open-source software projects.
In a blog post published shortly after the summit, Kent Walker, president for global affairs and chief legal officer at Google and Alphabet, said that collaboration between governmen
-
White House Convenes Open-Source Security Summit Amid Log4j Risks
The virtual summit, led by deputy national security adviser Anne Neuberger, included executives from Apple Inc., Alphabet Inc., Meta Platforms Inc. and Microsoft Corp. , among others, along with specialist open-source software organizations such as GitHub Inc., the Apache Software Foundation and the Linux Open Source Foundation.
The Cybersecurity and Infrastructure Security Agency, the Commerce Department, the Defense Department and the Energy Department were among the federal agencies present.
-

- Login or register to post comments
Printer-friendly version- 1269 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
digiKam 7.7.0 is released
After three months of active maintenance and another bug triage, the digiKam team is proud to present version 7.7.0 of its open source digital photo manager. See below the list of most important features coming with this release.
|
Dilution and Misuse of the "Linux" Brand
|
Samsung, Red Hat to Work on Linux Drivers for Future Tech
The metaverse is expected to uproot system design as we know it, and Samsung is one of many hardware vendors re-imagining data center infrastructure in preparation for a parallel 3D world.
Samsung is working on new memory technologies that provide faster bandwidth inside hardware for data to travel between CPUs, storage and other computing resources. The company also announced it was partnering with Red Hat to ensure these technologies have Linux compatibility.
|
today's howtos
|








.svg_.png)
Content (where original) is available under CC-BY-SA, copyrighted by original author/s.

Recent comments
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago